Main content

NIS2 requirements for software suppliers

Customers in NIS2 scope pass the requirements to their software suppliers through questionnaires and contracts. ELASTO answers them with evidence and closes the gaps they expose.

The request, on one sheet

Legal basis
Article 21, supply chain
Sent by
Customers in NIS2 scope
Sent to
Suppliers, in scope or not
Arrives as
A questionnaire, then clauses
Answered with
Settings, records, files

Supplier security under NIS2: how the requirement travels

A customer in scope proves supply chain security with its suppliers' evidence.

FIG. 1From the customer to the supplier
How NIS2 reaches a software supplier: the directive puts supply chain duties on a customer in scope, the customer sends a questionnaire and then contract clauses to its software supplier, and the supplier answers from an evidence folder: MFA report, restore test, SBOM per release, subprocessor list.DutiesQuestionnaireContract clausesNIS2Article 21Customer in scopeEssential or importantSoftware supplierIn scope or notEvidence folderKept currentMFA reportRestore testSBOM per releaseSubprocessor list

Why suppliers outside scope get pulled in

Article 21 makes supply chain security a minimum measure for every entity in scope, and asks each one to weigh the vulnerabilities of its direct suppliers, the quality of their products and their security practices, including secure development.

A customer can only show that work with evidence from the supplier. The first sign is usually a questionnaire, followed by contract clauses on incident notice, subcontractors and audit rights.

Suppliers in scope themselves

Managed service providers and managed security service providers sit in Annex I under ICT service management, so a mid-size or large software company that runs systems for its customers carries NIS2 duties directly.

NIS2 security questionnaire: the questions and the evidence

The wording changes; the topics repeat.

Answers with evidenceDemo data

53of 61

The rest go on the fix list

In every questionnaire

Incident noticeMFABackupsSubcontractorsVulnerability handlingSBOMSecure developmentAccess control

Eight topics and the evidence behind each

Incident notice
Asked: how fast the supplier reports an incident that affects the customer, and to whom. Evidence: an incident runbook with a contact list, and the notification time written into the contract.
MFA
Asked: whether every staff and admin account uses multi-factor authentication. Evidence: an enforcement report exported from the identity provider.
Backups
Asked: how often data is backed up and whether restores work. Evidence: a restore test record with the date, the data set and the time it took.
Subcontractors
Asked: which third parties touch the customer's data, and where. Evidence: a subprocessor list with location, purpose and the data each one receives.
Vulnerability handling
Asked: how vulnerabilities are found, fixed and disclosed. Evidence: dependency scan output, a patch record and a published disclosure contact in security.txt.
SBOM
Asked: which open source and third-party components ship in the product. Evidence: a machine-readable SBOM per release, in SPDX or CycloneDX format.
Secure development
Asked: how code is reviewed, tested and deployed. Evidence: branch protection settings, CI checks and a secrets policy.
Access control
Asked: who can reach production, and how leavers lose access. Evidence: an access list, offboarding records and a periodic access review.

Cyber Resilience Act vs NIS2 for software products

The CRA regulates products; NIS2 regulates organisations. A software company can face both.

FIG. 2Cyber Resilience Act dates
  1. 10 December 2024

    Entry into force

    Law, with most duties still ahead.
  2. 11 September 2026

    Reporting duties

    Exploited vulnerabilities go to ENISA within 24 hours.
  3. 11 December 2027

    Full application

    CE marking and an SBOM for each product.

Where SaaS sits under the CRA

Pure SaaS usually falls outside the CRA unless it serves as the remote data processing of a product. The line depends on the product, so each case gets read against the text.

Last checked 28 September 2026, against Regulation (EU) 2024/2847.

NIS2 questionnaire review: answer, fix, set up

The questionnaire answered, the gaps closed and the evidence kept for the next one.

  1. Answer

    Every answer backed by a file, or given a fix date.
  2. Fix

    Gaps closed by risk: MFA, restore tests, an SBOM, patches.
  3. Set up

    An evidence folder kept current for the next customer.

ELASTO's own answers, as a supplier

ELASTO is a software supplier too. The security and disclosure page sets out how a vulnerability report reaches the studio, what happens to it and the measures behind this site.

On Mozar, where ELASTO is the software supplier, the same evidence is built into the platform. New web platforms ELASTO builds start from the same practices.

NIS2 for suppliers outside the EU

NIS2 does not bind a UK or North American company directly. Its EU customers still carry Article 21, so the questionnaire and the contract clauses arrive in the same way, and the evidence that answers them is identical. ELASTO works in English, Romanian and French from Cluj-Napoca, inside the EU.

NIS2 supplier questions

A customer's NIS2 questionnaire: where to start

A customer's NIS2 questionnaire starts with an inventory of what already exists: MFA settings, backup records, the subprocessor list, the patch process. Answers backed by evidence go first; the rest get their current status and a fix date. A dated plan holds up better than an unsupported yes.

NIS2 requirements for suppliers

NIS2 sets no separate list of supplier requirements. Suppliers get asked about the Article 21 measures their customers must run, mostly incident notice, MFA, backups, vulnerability handling, secure development and subcontractors. The contract then turns those answers into obligations, such as a notification deadline.

Suppliers outside the EU or outside NIS2 scope

The directive puts no direct duty on them. Their customers in scope carry it, and Article 21 makes them assess supplier practices, so the requirements arrive through questionnaires and contracts. For many customers, the answers decide whether a supplier stays on the approved vendor list.

NIS2 and SaaS providers

A SaaS provider falls under NIS2 directly when the annexes list its activity, for example cloud computing or managed services, and it is mid-size or large. Most SaaS vendors are not in scope themselves and meet NIS2 through their customers' questionnaires.

Cyber Resilience Act or NIS2 for a software product

The Cyber Resilience Act applies to software sold as a product in the EU; NIS2 applies to organisations in listed sectors and reaches suppliers through contracts. A company that sells an installable product can face both. CRA reporting duties apply from 11 September 2026 and the full requirements from 11 December 2027.

ISO 27001 certificate in place of the questionnaire

An ISO 27001 certificate shortens a NIS2 questionnaire but rarely replaces it. Customers still ask about incident notice times, subcontractors and the SBOM, which a certificate does not answer on its own. Attaching the certificate with its statement of applicability answers the control questions in one step.

The NIS2 gap analysis shows what the certificate leaves open.

NIS2 questionnaire review

The first call starts from the questionnaire itself and the systems it asks about.

Studio
Cluj-Napoca, Romania, EU